Lately, a penetration test is done using OWAPS ZAP tool in my application. I have not much knowledge of security testing. They found some vulnerability that is XSS Cross-Site Scripting (Persistent).
In the application, there is a simple module that contains both getting some HTML content from users and according to content users can messaging with each other. I understand the vulnerability that occurs while getting HTML codes from users and decode them with @Html.Raw(content). HtmlSanitizer fixed this kind of attack such as alerting with using a script (<script alert(1); /script>) in my application.
But I confused at some point. The other vulnerability arose while getting user's messages. It attacks with sending message 'onMouseOver=alert(1);' as input. My application takes this input as normal text and shows the message as text. I showed the messages also with razor-like @message.content and I didn't use any @Html attributes.
I don't understand the vulnerabilities sending onMouseOver=alert(1); as input. What could be the problem?